Uptime Hamster: 10d 12h 14mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza PayoutsKING

PayoutsKING

0 incidentes 0 paises 0 sectores ransomware Unknown Ultimo: -
Aliases: PK Crew, Payout$King, Payouts_KING, payoutsking, PayoutsMafia
Ver en IntelTracker → APTTrail →
PayoutsKING is a ransomware and extortion group that first emerged in April 2025. The group explicitly states it does not operate as a Ransomware-as-a-Service (RaaS) model and does not use affiliates, with its core actors directly conducting attacks. PayoutsKING is assessed with high confidence to be comprised of former BlackBasta affiliates, leveraging their prior social engineering tactics while introducing enhanced obfuscation and encryption capabilities. The group is financially motivated, employing a double extortion strategy that involves encrypting victim files and exfiltrating large volumes of data to pressure payment. A distinguishing characteristic is their rapid victim disclosure across diverse sectors and their claim of being a closed, independent operation, which sets them apart from the prevalent RaaS model in the ransomware landscape.

Aliases del actor

PK CrewPayout$KingPayouts_KINGpayoutskingPayoutsMafia

Actores similares

apt-hackingteamactor · 1Password Crackingactor · 1Blue Mockingbirdapt · 1iamthekingactor · 1the-whois-hacking-teamactor · 1black-kingdomactor · 1Hacking Teamapt · 0VIKING SPIDERapt · 0Viking Jackalapt · 0IMNCrewransomware · 2

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteupransomware.anggipradana.comRansomware Group: payoutsking
DLS / onionunknownpayoutsgn7cy6uliwevdqspncjpfxpmzgirwl2au65la7rfs5x3qnbqd.onionC****h
DLS / onionunknownpayoutsgn7cy6uliwevdqspncjpfxpmzgirwl2au65la7rfs5x3qnbqd.onionC****h
Malware asociado
Octo, Anubis, Anubis, Octo, Anubis
Tecnicas MITRE
T1071.001, T1056.001, T1071 -, T1566 -, T1204.002, T1059 -
Tipo
ransomware
Pais origen
Unknown
Motivacion
-
Impacto
75
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

AustriaAustraliaBangladeshBelgiumBulgariaBrazilCanadaSwitzerlandCôte d'IvoireChile

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsAccommodationAir TransportationManufacturingConstruction